sast-businesslogic

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and mostly local-only, but its stated purpose is to equip an AI agent with offensive security analysis for business logic exploitation. There are no clear exfiltration, credential-harvesting, or supply-chain red flags in the provided text, yet the exploit-finding and dynamic-test generation make it a high-risk security skill rather than a benign developer helper.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-businesslogic%2F@ab96738e2b71ee55215075b0e586cb9764c56921